EU regulator ESMA launches dedicated review process for crypto custody providers under MiCA transition.
Regulation & Gov ·
The European Securities and Markets Authority has launched its first Common Supervisory Action targeting crypto-asset service providers since MiCA entered full enforcement, with a focus on digital operational resilience of custody services. National regulators across the EU will conduct risk-based assessments examining governance structures, cryptographic key management, transaction controls, incident response protocols, smart contract vulnerabilities, and reliance on third-party providers through 2027.
This coordinated review represents the regulator's initial enforcement push under MiCA's full implementation phase. The action follows the transition period and reflects ESMA's intention to standardize supervision of custodial operations across member states, where practices and safeguards have historically varied. The multi-year timeline suggests a phased approach rather than a single examination cycle.
The scope and specific findings from individual national regulators remain undisclosed at this stage. It is unclear whether the review will result in binding operational standards, fines, or enforcement actions against particular providers, or how findings will be weighted and consolidated across jurisdictions.